Skip to main content

Customer Credential Exposure

Updated over 2 months ago

What is the Customer Credential Exposure?

Customer Credential Exposure is the recommended solution for companies that have products or services with a login area, where customers need to log in using a username and password.

With Customer Credential Exposure, it is possible to identify if your users are using compromised passwords leaked from third-party services associated with their registered email. Customer Credential Exposure makes your product or service more secure by preventing unauthorized access to registered user accounts through attacks like Credential Stuffing.


Why use the Customer Credential Exposure?

Customer Credential Exposure quickly detects the use of compromised user credentials leaked on the internet (Surface Web, Deep & Dark Web). It significantly minimizes the impact of corporate credential leaks.

Customer Credential Exposure alerts possible accounts that could be fraudulently used by attackers who gained access to leaked user passwords on the internet.


How do I consume Customer Credential Exposure data?

Customer Credential Exposure monitors credential leaks and alerts when it identifies the exposure of customer credentials through API queries and webhook alerts.

The API returns the hash of the leaked credential, the password hash, and the detection date, while the webhook notifies about new leaks to previously registered emails.


Are the credentials sent encrypted?

Yes. You send Axur the encrypted list (XXH64) of emails, and Axur returns the list of leaked emails (along with the encrypted password) so that the client can reset the password for the leaked credentials.

Thus, it complies with the requirements of the General Data Protection Law by sharing information with clients in an encrypted and anonymous manner.


How do I access the API?

Upon subscribing to the service, you will be granted API access. For detailed instructions on making API queries, kindly refer to the documentation.


What is the difference between Customer Credential Exposure and Corporate Credential Leak?

Corporate Credential Leak monitors leaked emails and credentials from corporate domains for the companies that own these domains.

Customer Credential Exposure goes further and allows companies that have a login area and a registered customer base to check if their users have any leaked credentials in exposed databases, preventing their users from reusing those credentials in their system.


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?